PT-2007-1115 · Kde+1 · Kdm+1

Kees Huijgen

·

Publicado

2007-09-21

·

Atualizado

2017-09-29

·

CVE-2007-4569

CVSS v2.0

6.8

Média

VetorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: KDM versions 3.3.0 through 3.5.7
Description: The issue allows remote attackers to bypass the password requirement and login to arbitrary accounts via unspecified vectors when autologin is configured and "shutdown with password" is enabled. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out locally by an attacker who has passed the authentication procedure.
Recommendations: For KDM versions 3.3.0 through 3.5.7, update to version 3.5.7-r2 or later to resolve the issue. As a temporary workaround, consider disabling the autologin feature and the "shutdown with password" option to minimize the risk of exploitation. Restrict access to the backend/session.c component in KDM to reduce the risk of unauthorized access.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09598
CVE-2007-4569
DSA-1376-1
DTSA-60-1
RHSA-2007:0905
RHSA-2007_0905

Produtos afetados

Kdm
Red Hat